PlantKeeper: Datenschutzerklärung
Kurzfassung: so wenig wie möglich, kein Werbe-Tracking, keine Weitergabe zu Werbezwecken, kein Verkauf von Daten. Was trotzdem anfällt, steht hier vollständig. Diese Erklärung gilt für plantkeeper.de, app.plantkeeper.de, api.plantkeeper.de und die App PlantKeeper für Android und iOS.
Verantwortlicher
Alexander West · [email protected]
Anschrift siehe Impressum.
Ein Datenschutzbeauftragter ist nicht bestellt; die gesetzlichen Voraussetzungen dafür liegen nicht vor.
Warteliste
- Was: deine E-Mail-Adresse, deine Auswahl (derzeit immer Fertiggerät), optional die Preisspanne, der Anmeldezeitpunkt und, falls du über einen Link mit Quellenangabe kommst (z. B. aus einer YouTube-Beschreibung), diese Quelle als kurzes Kürzel.
- Wofür: dich einmalig zu informieren, wenn PlantKeeper startet (Art. 6 Abs. 1 lit. a DSGVO: deine Einwilligung). Das Häkchen zur Speicherung ist Pflichtfeld.
- Bestätigungsmail: die Eintragung wird derzeit nicht per Mail bestätigt, es gibt also kein Double-Opt-in. Vor der ersten Massenmail wird das nachgeholt.
- Was nicht: kein Newsletter, keine Werbung Dritter, keine Weitergabe, kein Profiling, keine Analyse-Cookies. Die Seite setzt keine Cookies; lokal in deinem Browser gespeichert wird nur deine Sprachwahl (localStorage-Eintrag trinkLang), damit die Seite beim nächsten Besuch in derselben Sprache erscheint.
- Wie lange: bis zum Produktstart plus der Start-Mail, oder bis du dich austrägst. Danach wird die Adresse gelöscht.
- Austragen: jederzeit formlos per Mail an [email protected]. Der Eintrag wird vollständig gelöscht.
Nutzerkonto in der App
- Was: deine E-Mail-Adresse, ein bcrypt-Hash deines Passworts mit Zufallssalz (das Passwort selbst wird nie gespeichert) und der Zeitpunkt der Registrierung.
- Anmeldung: nach dem Login liegt ein Anmelde-Token (JWT) mit einer Laufzeit von 90 Tagen im verschlüsselten Speicher deines Betriebssystems (Android EncryptedSharedPreferences, iOS-Schlüsselbund). Beim Abmelden wird es gelöscht. Nutzt du statt der App den Web-Client unter app.plantkeeper.de, liegen Token und E-Mail-Adresse im sessionStorage des Browsers und sind weg, sobald du den Tab schließt.
- Betrieb: der Zeitpunkt deiner letzten Anmeldung und die Version der App, die sich zuletzt gemeldet hat. Beides beantwortet, ob ein Konto noch benutzt wird und welche App-Version dort läuft.
- Wofür: Anmeldung, Zuordnung deiner Geräte, Schutz vor fremdem Zugriff (Art. 6 Abs. 1 lit. b DSGVO); der Anmeldezeitpunkt und die App-Version zusätzlich für Betrieb und Fehlersuche (Art. 6 Abs. 1 lit. f DSGVO).
Gerätedaten
- Was: Geräte-ID (z. B. trink-f13144), das Geräte-Secret, der von dir vergebene Gerätename und der Zeitpunkt des letzten Kontakts.
- Gerätezustand: der zuletzt gemeldete Zustand als Ganzes, darin u. a. Akkuspannung und -stand, Tankfüllung, Boden-Rechenwerte, letzte Gießmenge und -zeit, Firmware-Version, Hardware-Modell, WLAN-Feldstärke, Schlafintervall und deine Geräteeinstellungen. Dazu, sobald du einen Standort gesetzt hast, der Ortsname und die Koordinaten deines Beets auf vier Nachkommastellen (etwa 11 m), sowie der Name deines WLANs (SSID), den das Gerät mitmeldet.
- Befehle: was du an das Gerät schickst, samt Status und Quittung, die jeweils letzten 40 Einträge je Gerät. Ältere fallen automatisch weg.
- Gerätemeldungen: Hinweise des Geräts (Frost, Tank leer, Tagesgabe).
- Zähler: ein Tageszähler der Kontaktaufnahmen, rollierend über 14 Tage.
- Wofür: Anzeige und Fernsteuerung deines Geräts, Fehlersuche (Art. 6 Abs. 1 lit. b DSGVO).
Messreihen
- Was: alle 15 Minuten ein Messpunkt je Gerät mit Zeitstempel, Akkuspannung, Akkustand in Prozent, Tankfüllung und der Angabe, ob gerade geladen wird.
- Wofür: die Verlaufsanzeige in der App und die Fehlersuche (Art. 6 Abs. 1 lit. b DSGVO); für den Jahresvergleich über die Anzeige hinaus Art. 6 Abs. 1 lit. f DSGVO.
- Wie lange: zwei Jahre. Ältere Messpunkte löscht der Server automatisch. Die App ruft ohnehin höchstens die letzten 365 Tage ab.
- Sofort weg: wenn du das Gerät aus deinem Konto entfernst, es auf Werkseinstellungen zurücksetzt oder dein Konto löschst.
Standort und Bluetooth in der App
Warum Bluetooth? Ein neues PlantKeeper-Gerät wird per Bluetooth eingerichtet: die App sucht das Gerät in Funkreichweite und überträgt WLAN-Zugangsdaten, Einstellungen und, auf deinen Tipp hin, den Standort. Die WLAN-Zugangsdaten gehen dabei direkt vom Telefon an das Gerät, nicht über den Server. Auf Android ist die Bluetooth-Suche ausdrücklich als "leitet keinen Standort ab" gekennzeichnet (neverForLocation); auf Android 11 und älter verlangt das System für eine Bluetooth-Suche technisch trotzdem die Standortberechtigung, die App wertet den Standort dabei nicht aus.
Warum Standort? Ausschließlich, damit dein Gerät die Wettervorhersage am richtigen Ort abruft. Die App fragt einmalig und nur nach einem ausdrücklichen Tippen auf den Knopf, holt eine grobe Ortung und schreibt sie per Bluetooth an das Gerät. Es gibt keine Ortung im Hintergrund, keine wiederholte Abfrage und keine Bewegungsprofile. Wer den Standort nicht geben möchte, tippt stattdessen den Ortsnamen ein.
Der Rückweg: beim nächsten Kontakt des Geräts mit dem Server sind die Koordinaten Teil des Gerätezustands (siehe Gerätedaten) und liegen dann auch auf dem Server. Rechtsgrundlage für die Ortung im Telefon ist deine Einwilligung über den Systemdialog (Art. 6 Abs. 1 lit. a DSGVO), für die Nutzung im Gerät und in der App Art. 6 Abs. 1 lit. b DSGVO.
Um zu deinen Koordinaten einen Ortsnamen anzuzeigen, nutzt die App den im Betriebssystem eingebauten Geocoder. Ein eigener Netzdienst wird dabei nicht angesprochen.
Wetterdaten
Das Gerät fragt die Vorhersage selbst ab, direkt aus deinem WLAN. An api.open-meteo.com gehen dabei die Koordinaten deines Beets und die IP-Adresse deines Internetanschlusses. Trägst du einen Ortsnamen statt Koordinaten ein, geht dieser Ortsname an geocoding-api.open-meteo.com, um daraus Koordinaten zu machen. Ein Konto oder eine Kennung wird nicht mitgeschickt.
Der Server fragt zusätzlich für die Anzeige in der App ab, aber nicht je Gerät: gecacht wird je Gitterzelle von 0,1 Grad (etwa 11 km, gerundet). Dabei gehen nur diese gerundeten Koordinaten und die IP-Adresse des Servers hinaus, keine Geräte- oder Kontokennung.
Trägst du einen Ortsnamen ein, schickt auch der Server diesen Namen an geocoding-api.open-meteo.com, um daraus Koordinaten zu machen, und merkt sich das Ergebnis (Ortsname, Koordinaten, Zeitpunkt) in einem Cache. Ein Eintrag, den 30 Tage niemand mehr gebraucht hat, wird gelöscht. Auch dabei geht keine Geräte- oder Kontokennung hinaus.
Betreiber ist Open-Meteo mit Sitz in der Schweiz (Datenschutzhinweise). Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO, ohne diese Abfrage kann das Gerät nicht bedarfsgerecht gießen.
Push-Benachrichtigungen
- Was: ein Push-Token je App-Installation, dazu die Plattform (Android oder iOS) und der Zeitpunkt.
- Wer: die Zustellung läuft über Firebase Cloud Messaging (FCM) von Google, auf iOS über Apple Push Notification service (APNs) hinter FCM. Empfänger ist Google Ireland Ltd.
- Inhalte: die Gerätemeldungen (Frost, Tank leer, Tagesgabe).
- Wofür: dich über den Zustand deines Geräts informieren (Art. 6 Abs. 1 lit. b DSGVO).
- Abschalten: in den Systemeinstellungen deines Telefons. Dann werden keine Pushes mehr zugestellt.
Diagnosedaten in der App
- Was: stürzt die App ab oder läuft sie in einen Fehler, geht ein technischer Bericht an einen eigenen Server in Deutschland (GlitchTip): Fehlermeldung, Programmstelle, App- und Geräteversion, Zeitpunkt.
- Was nicht: keine IP-Adresse, kein Name, keine Kontaktdaten, keine Inhalte deiner Gerätedaten.
- Wofür: Fehler finden und beheben (Art. 6 Abs. 1 lit. f DSGVO: berechtigtes Interesse an einer funktionierenden App).
- Abschalten: in der App im Konto-Menü unter "Diagnosedaten". Danach wird nichts mehr gesendet.
- Wie lange: 90 Tage, danach automatische Löschung.
Reichweitenmessung (Plausible)
Die Startseite nutzt eine selbst betriebene Instanz von Plausible Analytics, um zu zählen, wie viele Menschen die Seite besuchen und ob sich jemand in die Warteliste einträgt (Art. 6 Abs. 1 lit. f DSGVO: berechtigtes Interesse an anonymer Reichweitenmessung). Plausible setzt keine Cookies, speichert keine IP-Adressen und bildet keine personenbezogenen Profile; die Daten liegen auf demselben selbst betriebenen Server. Beim Wartelisten-Eintrag wird nur die gewählte Preisspanne und die Sprache gezählt, nie die E-Mail-Adresse.
Server-Logs und Cloudflare
Der Server verarbeitet die IP-Adresse des Aufrufs technisch bedingt zur Auslieferung und für Rate-Limits (Missbrauchsschutz, Art. 6 Abs. 1 lit. f DSGVO). Sie wird nur flüchtig im Arbeitsspeicher für die Zählung der letzten 60 Sekunden gehalten und nicht mit dem Konto oder der Warteliste verknüpft. Ein Zugriffs-Log führt der Server nicht: das Access-Log der Anwendung ist abgeschaltet, damit keine IP-Adressen in Log-Dateien landen. Gezählt wird nur, wie viele Aufrufe je Tag auf welche Gruppe von Adressen fielen, ohne IP und ohne Kontobezug.
Der Server steht selbst betrieben in Deutschland, erreichbar über Cloudflare. Cloudflare terminiert dabei die TLS-Verbindung und verarbeitet damit sämtliche Anfragedaten einschließlich IP-Adressen. Cloudflare ist insoweit Auftragsverarbeiter; Grundlage ist der Auftragsverarbeitungsvertrag (Cloudflare DPA) nach Art. 28 DSGVO, für die USA gestützt auf EU-Standardvertragsklauseln und das EU-US Data Privacy Framework.
Speicherdauer
- Konto: bis zur Löschung, die du selbst in der App auslösen kannst.
- Gerätedaten: bis du das Gerät aus dem Konto entfernst oder es auf Werkseinstellungen zurücksetzt. Ein herrenloses Gerät, das sich 90 Tage nicht mehr meldet, wird ganz gelöscht.
- Befehle und Quittungen: die letzten 40 Einträge je Gerät.
- Messreihen: zwei Jahre.
- Warteliste: bis zur Start-Mail oder bis zur Austragung.
- Wetter- und Ortsnamen-Cache: 30 Tage, gerechnet ab dem letzten Mal, dass ein Eintrag gebraucht wurde.
- Diagnosedaten: 90 Tage.
- IP-Adressen: 60 Sekunden im Arbeitsspeicher, kein dauerhaftes Log.
Was nicht stattfindet
Keine Weitergabe zu Werbezwecken, kein Verkauf von Daten, kein Profiling, keine automatisierte Entscheidung im Einzelfall nach Art. 22 DSGVO, keine Werbe-Cookies, keine Werbenetzwerke. Außer den hier genannten Empfängern werden keine Daten an Dritte weitergegeben.
Deine Rechte
Du hast das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch gegen Verarbeitungen auf Grundlage berechtigter Interessen (Art. 21 DSGVO). Erteilte Einwilligungen kannst du jederzeit mit Wirkung für die Zukunft widerrufen (Art. 7 Abs. 3 DSGVO); die Rechtmäßigkeit der bis dahin erfolgten Verarbeitung bleibt unberührt. Eine formlose Mail an [email protected] genügt.
Außerdem kannst du dich bei einer Aufsichtsbehörde beschweren (Art. 77 DSGVO). Zuständig ist das Bayerische Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, oder die Behörde deines gewöhnlichen Aufenthaltsorts.
Konto löschen
Du löschst dein Konto selbst in der App: Konto-Menü, "Konto löschen", Bestätigung mit deinem Passwort. Danach passiert Folgendes: das Konto samt E-Mail-Adresse, Passwort-Hash und Push-Token ist weg. Deine Geräte werden herrenlos und behalten keine Daten: Verlauf, Meldungen, Gieß-Historie, Zustand und Name werden sofort gelöscht. Für jedes Gerät wird ein Werksreset eingereiht, den es beim nächsten Kontakt abholt; danach ist auch die Gerätezeile weg. Meldet sich ein Gerät nie mehr, wird die Zeile nach 90 Tagen ohne Kontakt gelöscht.
PlantKeeper: Privacy Policy
Short version: as little as possible, no advertising trackers, no sharing for advertising, no selling of data. Everything that does come up is listed here. This policy covers plantkeeper.de, app.plantkeeper.de, api.plantkeeper.de and the PlantKeeper app for Android and iOS.
Who is responsible
Alexander West · [email protected]
Postal address in the legal notice.
No data protection officer has been appointed; the legal conditions requiring one are not met.
Waitlist
- What: your email address, your choice (currently always the finished device), optionally a price band, the sign-up time and, if you arrive via a tagged link (e.g. from a YouTube description), that source as a short tag.
- Why: to notify you once when PlantKeeper launches (Art. 6(1)(a) GDPR: your consent). The storage checkbox is mandatory.
- Confirmation email: sign-ups are currently not confirmed by email, so there is no double opt-in. This will be added before the first bulk email.
- Not happening: no newsletter, no third-party ads, no sharing, no profiling, no analytics cookies. The page sets no cookies; the only thing stored locally in your browser is your language choice (localStorage entry trinkLang), so the page comes back in the same language.
- How long: until launch plus the launch email, or until you unsubscribe. The address is deleted afterwards.
- Unsubscribe: any time, a plain email to [email protected] is enough. The entry is deleted completely.
User account in the app
- What: your email address, a bcrypt hash of your password with a random salt (the password itself is never stored) and the time you registered.
- Sign-in: after login a sign-in token (JWT) valid for 90 days is kept in your operating system's encrypted storage (Android EncryptedSharedPreferences, iOS keychain). Logging out deletes it. If you use the web client at app.plantkeeper.de instead of the app, the token and your email address sit in the browser's sessionStorage and are gone as soon as you close the tab.
- Operations: the time of your last sign-in and the version of the app that last reported in. Both answer whether an account is still in use and which app version runs there.
- Why: sign-in, mapping devices to you, protection against access by others (Art. 6(1)(b) GDPR); the sign-in time and app version additionally for operations and troubleshooting (Art. 6(1)(f) GDPR).
Device data
- What: device ID (e.g. trink-f13144), the device secret, the device name you chose and the time it was last in contact.
- Device state: the last reported state as a whole, including battery voltage and level, tank level, soil calculations, last watering amount and time, firmware version, hardware model, Wi-Fi signal strength, sleep interval and your device settings. Plus, once you have set a location, the place name and the coordinates of your plants to four decimal places (about 11 m), and the name of your Wi-Fi network (SSID), which the device reports along with its state.
- Commands: what you send to the device, with status and acknowledgement, the last 40 entries per device. Older ones are dropped automatically.
- Device notices: messages from the device (frost, empty tank, daily dose).
- Counters: a daily counter of contacts, rolling over 14 days.
- Why: showing and controlling your device remotely, troubleshooting (Art. 6(1)(b) GDPR).
Measurement series
- What: one data point per device every 15 minutes with timestamp, battery voltage, battery level in percent, tank level and whether it is charging.
- Why: the history view in the app and troubleshooting (Art. 6(1)(b) GDPR); for year-on-year comparison beyond the display, Art. 6(1)(f) GDPR.
- How long: two years. Older points are deleted automatically by the server. The app only ever fetches the last 365 days.
- Deleted at once: when you remove the device from your account, factory-reset it or delete your account.
Location and Bluetooth in the app
Why Bluetooth? A new PlantKeeper device is set up over Bluetooth: the app looks for the device in radio range and transfers Wi-Fi credentials, settings and, when you tap for it, the location. Wi-Fi credentials go straight from the phone to the device, not through the server. On Android the Bluetooth scan is explicitly flagged as "derives no location" (neverForLocation); on Android 11 and older the system still technically requires the location permission for a Bluetooth scan, and the app does not evaluate location there.
Why location? Only so your device fetches the weather forecast for the right place. The app asks once and only after you explicitly tap the button, takes a coarse fix and writes it to the device over Bluetooth. There is no background location, no repeated polling and no movement profiles. If you would rather not share a location, type the place name instead.
The way back: the next time the device contacts the server, the coordinates are part of the device state (see device data) and are then stored on the server too. The legal basis for the fix on the phone is your consent via the system dialog (Art. 6(1)(a) GDPR), for its use in the device and the app Art. 6(1)(b) GDPR.
To show a place name for your coordinates the app uses the geocoder built into the operating system. No separate network service is contacted.
Weather data
The device fetches the forecast itself, straight from your Wi-Fi. The coordinates of your plants and the IP address of your internet connection go to api.open-meteo.com. If you enter a place name instead of coordinates, that name goes to geocoding-api.open-meteo.com to be turned into coordinates. No account and no identifier is sent along.
The server additionally fetches the forecast for the display in the app, but not per device: it caches per grid cell of 0.1 degrees (about 11 km, rounded). Only those rounded coordinates and the server's IP address leave the server, no device or account identifier.
If you enter a place name, the server also sends that name to geocoding-api.open-meteo.com to turn it into coordinates and keeps the result (place name, coordinates, time) in a cache. An entry nobody has needed for 30 days is deleted. No device or account identifier is sent here either.
The operator is Open-Meteo, based in Switzerland (privacy information). Legal basis: Art. 6(1)(b) GDPR, without this request the device cannot water according to need.
Push notifications
- What: one push token per app installation, plus the platform (Android or iOS) and the time.
- Who: delivery runs through Firebase Cloud Messaging (FCM) by Google, on iOS through Apple Push Notification service (APNs) behind FCM. The recipient is Google Ireland Ltd.
- Content: the device notices (frost, empty tank, daily dose).
- Why: to tell you about the state of your device (Art. 6(1)(b) GDPR).
- Turning it off: in your phone's system settings. No further pushes are delivered then.
Diagnostic data in the app
- What: if the app crashes or hits an error, a technical report goes to a self-hosted server in Germany (GlitchTip): error message, code location, app and device version, time.
- Not included: no IP address, no name, no contact details, none of your device data.
- Why: finding and fixing errors (Art. 6(1)(f) GDPR: legitimate interest in a working app).
- Turning it off: in the app under "Diagnosedaten" in the account menu. Nothing is sent afterwards.
- How long: 90 days, then automatic deletion.
Analytics (Plausible)
The landing page uses a self-hosted Plausible Analytics instance to count how many people visit the page and whether someone signs up for the waitlist (Art. 6(1)(f) GDPR: legitimate interest in anonymous reach measurement). Plausible sets no cookies, stores no IP addresses and builds no personal profiles; the data stays on the same self-hosted server. On waitlist sign-up only the chosen price band and the language are counted, never the email address.
Server logs and Cloudflare
The server processes the IP address of a request for delivery and for rate limiting (abuse protection, Art. 6(1)(f) GDPR). It is held only briefly in memory to count the last 60 seconds and is not linked to your account or the waitlist. The server keeps no access log: the application's access log is switched off so that no IP addresses end up in log files. All that is counted is how many requests per day hit which group of endpoints, without IP and without any link to an account.
The server is self-hosted in Germany and reachable through Cloudflare. Cloudflare terminates the TLS connection and thereby processes all request data including IP addresses. Cloudflare acts as a processor in that respect; the basis is the Cloudflare data processing addendum under Art. 28 GDPR, for the USA backed by EU standard contractual clauses and the EU-US Data Privacy Framework.
Retention
- Account: until deletion, which you can trigger yourself in the app.
- Device data: until you remove the device from your account or factory-reset it. An unowned device that stops reporting for 90 days is deleted entirely.
- Commands and acknowledgements: the last 40 entries per device.
- Measurement series: two years.
- Waitlist: until the launch email or until you unsubscribe.
- Weather and place-name cache: 30 days, counted from the last time an entry was needed.
- Diagnostic data: 90 days.
- IP addresses: 60 seconds in memory, no persistent log.
What does not happen
No sharing for advertising, no selling of data, no profiling, no automated individual decision-making under Art. 22 GDPR, no advertising cookies, no ad networks. Apart from the recipients named here, no data is passed to third parties.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Consent you have given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of processing up to that point is unaffected. A plain email to [email protected] is enough.
You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent one is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 27, 91522 Ansbach, or the authority where you usually live.
Deleting your account
You delete your account yourself in the app: account menu, "Konto löschen", confirmed with your password. What happens then: the account with your email address, password hash and push token is gone. Your devices become unowned and keep no data: history, notices, watering history, state and name are deleted immediately. A factory reset is queued for each device and picked up on its next contact; after that the device row is gone too. If a device never reports again, its row is deleted after 90 days without contact.